vulnerability

Rocky Linux: CVE-2022-26305: libreoffice (Multiple Advisories)

Severity
8
CVSS
(AV:N/AC:H/Au:N/C:C/I:C/A:C)
Published
Jul 25, 2022
Added
Mar 12, 2024
Modified
Aug 13, 2025

Description

An Improper Certificate Validation vulnerability in LibreOffice existed where determining if a macro was signed by a trusted author was done by only matching the serial number and issuer string of the used certificate with that of a trusted certificate. This is not sufficient to verify that the macro was actually signed with the certificate. An adversary could therefore create an arbitrary certificate with a serial number and an issuer string identical to a trusted certificate which LibreOffice would present as belonging to the trusted author, potentially leading to the user to execute arbitrary code contained in macros improperly trusted. This issue affects: The Document Foundation LibreOffice 7.2 versions prior to 7.2.7; 7.3 versions prior to 7.3.1.

Solutions

rocky-upgrade-libreoffice-baserocky-upgrade-libreoffice-base-debuginforocky-upgrade-libreoffice-calcrocky-upgrade-libreoffice-calc-debuginforocky-upgrade-libreoffice-corerocky-upgrade-libreoffice-core-debuginforocky-upgrade-libreoffice-debuginforocky-upgrade-libreoffice-drawrocky-upgrade-libreoffice-emailmergerocky-upgrade-libreoffice-filtersrocky-upgrade-libreoffice-gdb-debug-supportrocky-upgrade-libreoffice-graphicfilterrocky-upgrade-libreoffice-graphicfilter-debuginforocky-upgrade-libreoffice-gtk3rocky-upgrade-libreoffice-gtk3-debuginforocky-upgrade-libreoffice-help-arrocky-upgrade-libreoffice-help-bgrocky-upgrade-libreoffice-help-bnrocky-upgrade-libreoffice-help-carocky-upgrade-libreoffice-help-csrocky-upgrade-libreoffice-help-darocky-upgrade-libreoffice-help-derocky-upgrade-libreoffice-help-dzrocky-upgrade-libreoffice-help-elrocky-upgrade-libreoffice-help-enrocky-upgrade-libreoffice-help-eorocky-upgrade-libreoffice-help-esrocky-upgrade-libreoffice-help-etrocky-upgrade-libreoffice-help-eurocky-upgrade-libreoffice-help-firocky-upgrade-libreoffice-help-frrocky-upgrade-libreoffice-help-glrocky-upgrade-libreoffice-help-gurocky-upgrade-libreoffice-help-herocky-upgrade-libreoffice-help-hirocky-upgrade-libreoffice-help-hrrocky-upgrade-libreoffice-help-hurocky-upgrade-libreoffice-help-idrocky-upgrade-libreoffice-help-itrocky-upgrade-libreoffice-help-jarocky-upgrade-libreoffice-help-korocky-upgrade-libreoffice-help-ltrocky-upgrade-libreoffice-help-lvrocky-upgrade-libreoffice-help-nbrocky-upgrade-libreoffice-help-nlrocky-upgrade-libreoffice-help-nnrocky-upgrade-libreoffice-help-plrocky-upgrade-libreoffice-help-pt-brrocky-upgrade-libreoffice-help-pt-ptrocky-upgrade-libreoffice-help-rorocky-upgrade-libreoffice-help-rurocky-upgrade-libreoffice-help-sirocky-upgrade-libreoffice-help-skrocky-upgrade-libreoffice-help-slrocky-upgrade-libreoffice-help-svrocky-upgrade-libreoffice-help-tarocky-upgrade-libreoffice-help-trrocky-upgrade-libreoffice-help-ukrocky-upgrade-libreoffice-help-zh-hansrocky-upgrade-libreoffice-help-zh-hantrocky-upgrade-libreoffice-impressrocky-upgrade-libreoffice-impress-debuginforocky-upgrade-libreoffice-langpack-afrocky-upgrade-libreoffice-langpack-arrocky-upgrade-libreoffice-langpack-asrocky-upgrade-libreoffice-langpack-bgrocky-upgrade-libreoffice-langpack-bnrocky-upgrade-libreoffice-langpack-brrocky-upgrade-libreoffice-langpack-carocky-upgrade-libreoffice-langpack-csrocky-upgrade-libreoffice-langpack-cyrocky-upgrade-libreoffice-langpack-darocky-upgrade-libreoffice-langpack-derocky-upgrade-libreoffice-langpack-dzrocky-upgrade-libreoffice-langpack-elrocky-upgrade-libreoffice-langpack-enrocky-upgrade-libreoffice-langpack-eorocky-upgrade-libreoffice-langpack-esrocky-upgrade-libreoffice-langpack-etrocky-upgrade-libreoffice-langpack-eurocky-upgrade-libreoffice-langpack-farocky-upgrade-libreoffice-langpack-firocky-upgrade-libreoffice-langpack-frrocky-upgrade-libreoffice-langpack-fyrocky-upgrade-libreoffice-langpack-garocky-upgrade-libreoffice-langpack-glrocky-upgrade-libreoffice-langpack-gurocky-upgrade-libreoffice-langpack-herocky-upgrade-libreoffice-langpack-hirocky-upgrade-libreoffice-langpack-hrrocky-upgrade-libreoffice-langpack-hurocky-upgrade-libreoffice-langpack-idrocky-upgrade-libreoffice-langpack-itrocky-upgrade-libreoffice-langpack-jarocky-upgrade-libreoffice-langpack-kkrocky-upgrade-libreoffice-langpack-knrocky-upgrade-libreoffice-langpack-korocky-upgrade-libreoffice-langpack-ltrocky-upgrade-libreoffice-langpack-lvrocky-upgrade-libreoffice-langpack-mairocky-upgrade-libreoffice-langpack-mlrocky-upgrade-libreoffice-langpack-mrrocky-upgrade-libreoffice-langpack-nbrocky-upgrade-libreoffice-langpack-nlrocky-upgrade-libreoffice-langpack-nnrocky-upgrade-libreoffice-langpack-nrrocky-upgrade-libreoffice-langpack-nsorocky-upgrade-libreoffice-langpack-orrocky-upgrade-libreoffice-langpack-parocky-upgrade-libreoffice-langpack-plrocky-upgrade-libreoffice-langpack-pt-brrocky-upgrade-libreoffice-langpack-pt-ptrocky-upgrade-libreoffice-langpack-rorocky-upgrade-libreoffice-langpack-rurocky-upgrade-libreoffice-langpack-sirocky-upgrade-libreoffice-langpack-skrocky-upgrade-libreoffice-langpack-slrocky-upgrade-libreoffice-langpack-srrocky-upgrade-libreoffice-langpack-ssrocky-upgrade-libreoffice-langpack-strocky-upgrade-libreoffice-langpack-svrocky-upgrade-libreoffice-langpack-tarocky-upgrade-libreoffice-langpack-terocky-upgrade-libreoffice-langpack-throcky-upgrade-libreoffice-langpack-tnrocky-upgrade-libreoffice-langpack-trrocky-upgrade-libreoffice-langpack-tsrocky-upgrade-libreoffice-langpack-ukrocky-upgrade-libreoffice-langpack-verocky-upgrade-libreoffice-langpack-xhrocky-upgrade-libreoffice-langpack-zh-hansrocky-upgrade-libreoffice-langpack-zh-hantrocky-upgrade-libreoffice-langpack-zurocky-upgrade-libreoffice-mathrocky-upgrade-libreoffice-ogltransrocky-upgrade-libreoffice-ogltrans-debuginforocky-upgrade-libreoffice-pdfimportrocky-upgrade-libreoffice-pdfimport-debuginforocky-upgrade-libreoffice-pyunorocky-upgrade-libreoffice-pyuno-debuginforocky-upgrade-libreoffice-sdkrocky-upgrade-libreoffice-sdk-debuginforocky-upgrade-libreoffice-sdk-docrocky-upgrade-libreoffice-urerocky-upgrade-libreoffice-ure-debuginforocky-upgrade-libreoffice-wiki-publisherrocky-upgrade-libreoffice-writerrocky-upgrade-libreoffice-writer-debuginforocky-upgrade-libreoffice-x11rocky-upgrade-libreoffice-x11-debuginforocky-upgrade-libreoffice-xsltfilterrocky-upgrade-libreofficekitrocky-upgrade-libreofficekit-debuginfo
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.